In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_inherit_dacl() walks the parent directory DACL loaded from the security descriptor xattr. It verifies that each ACE contains the fixed SID header before using it, but does not verify that the variable-length SID described by sid.num_subauth is fully contained in the ACE. A malformed inheritable ACE can advertise more subauthorities than are present in the ACE. compare_sids() may then read past the ACE. smb_set_ace() also clamps the copied destination SID, but used the unchecked source SID count to compute the inherited ACE size. That could advance the temporary inherited ACE buffer pointer and nt_size accounting past the allocated buffer. Fix this by validating the parent ACE SID count and SID length before using the SID during inheritance. Compute the inherited ACE size from the copied SID so the size matches the bounded destination SID. Reject the inherited DACL if size accumulation would overflow smb_acl.size or the security descriptor allocation size.
Update Linux/Linux to a7fb771314fb3a265d30f8ac245869a367ab065c if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanksmbd: validate inherited ACE SID length affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_inherit_dacl() walks the parent directory DACL loaded from the security descriptor xattr. It verifies that each ACE contains the fixed SID header before using it, but does not verify that the variable-length SID described by sid.num_subauth is fully contained in the ACE. A malformed inheritable ACE can advertise more subauthorities than are present in the ACE. compare_sids() may then read past the ACE. smb_set_ace() also clamps the copied destination SID, but used the unchecked source SID count to compute the inherited ACE size. That could advance the temporary inherited ACE buffer pointer and nt_size accounting past the allocated buffer. Fix this by validating the parent ACE SID count and SID length before using the SID during inheritance. Compute the inherited ACE size from the copied SID so the size matches the bounded destination SID. Reject the inherited DACL if size accumulation would overflow smb_acl.size or the security descriptor allocation size.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_inherit_dacl() walks the parent directory DACL loaded from the security descriptor xattr. It verifies that each ACE contains the fixed SID header before using it, but does not verify that the variable-length SID described by sid.num_subauth is fully contained in the ACE. A malformed inheritable ACE can advertise more subauthorities than are present in the ACE. compare_sids() may then read past the ACE. smb_set_ace() also clamps the copied destination SID, but used the unchecked source SID count to compute the inherited ACE size. That could advance the temporary inherited ACE buffer pointer and nt_size accounting past the allocated buffer. Fix this by validating the parent ACE SID count and SID length before using the SID during inheritance. Compute the inherited ACE size from the copied SID so the size matches the bounded destination SID. Reject the inherited DACL if size accumulation would overflow smb_acl.size or the security descriptor allocation size.
Update Linux/Linux to a7fb771314fb3a265d30f8ac245869a367ab065c if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanksmbd: validate inherited ACE SID length affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_inherit_dacl() walks the parent directory DACL loaded from the security descriptor xattr. It verifies that each ACE contains the fixed SID header before using it, but does not verify that the variable-length SID described by sid.num_subauth is fully contained in the ACE. A malformed inheritable ACE can advertise more subauthorities than are present in the ACE. compare_sids() may then read past the ACE. smb_set_ace() also clamps the copied destination SID, but used the unchecked source SID count to compute the inherited ACE size. That could advance the temporary inherited ACE buffer pointer and nt_size accounting past the allocated buffer. Fix this by validating the parent ACE SID count and SID length before using the SID during inheritance. Compute the inherited ACE size from the copied SID so the size matches the bounded destination SID. Reject the inherited DACL if size accumulation would overflow smb_acl.size or the security descriptor allocation size.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
| Linux/Linuxgeneric | >=e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 <a7fb771314fb3a265d30f8ac245869a367ab065c || >=e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 <47c6e37a77b10e74f70d845ba4ea5d3cafa00336 || >=e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 <1aa60fea7f637c071f529ad6784aecca2f2f0c5f || >=e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 <c1d95c995d5bcb24b639200a899eda59cb1e6d64 || >=e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 <996454bc0da84d5a1dedb1a7861823087e01a7ae | a7fb771314fb3a265d30f8ac245869a367ab065c, 47c6e37a77b10e74f70d845ba4ea5d3cafa00336, 1aa60fea7f637c071f529ad6784aecca2f2f0c5f, c1d95c995d5bcb24b639200a899eda59cb1e6d64, 996454bc0da84d5a1dedb1a7861823087e01a7ae |
|---|---|---|
| Linux/Linuxgeneric | 5.15 | Not reported |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Package | Affected range | Fixed version |
|---|
| Linux/Linuxgeneric | >=e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 <a7fb771314fb3a265d30f8ac245869a367ab065c || >=e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 <47c6e37a77b10e74f70d845ba4ea5d3cafa00336 || >=e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 <1aa60fea7f637c071f529ad6784aecca2f2f0c5f || >=e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 <c1d95c995d5bcb24b639200a899eda59cb1e6d64 || >=e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 <996454bc0da84d5a1dedb1a7861823087e01a7ae | a7fb771314fb3a265d30f8ac245869a367ab065c, 47c6e37a77b10e74f70d845ba4ea5d3cafa00336, 1aa60fea7f637c071f529ad6784aecca2f2f0c5f, c1d95c995d5bcb24b639200a899eda59cb1e6d64, 996454bc0da84d5a1dedb1a7861823087e01a7ae |
|---|---|---|
| Linux/Linuxgeneric | 5.15 | Not reported |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard